Beginning July 27, 2026, GitHub will reduce public bug bounty payouts by at least 50% across all severity levels, moving top rewards to a permanent invite-only VIP tier. Critical findings in the public program will drop from $20,000-$30,000+ to a fixed $10,000, while the VIP tier offers $30,000 or more for critical vulnerabilities. The changes aim to reduce noise and prioritize quality over quantity, with GitHub stating, ‘You earn more by submitting better.’ The public program now features fixed payments: Low ($250), Medium ($2,000), High ($5,000), and Critical ($10,000). Researchers can qualify for the VIP program by reporting at least one critical, two high, four medium, or seven low-severity vulnerabilities. The announcement coincides with the rise of AI-assisted vulnerability discovery, as Google introduced Gemini 3.5 Flash Cyber, a model fine-tuned for finding and patching software flaws. GitHub’s restructuring follows a May 2026 policy requiring working proofs of concept and demonstrated impact. The shift reflects broader industry trends, with curl maintainer Daniel Stenberg ending cash bounties after AI-generated junk reports surged, though quality improved post-change. GitHub emphasizes that AI-assisted research is welcome but researchers must verify their findings.
Companies: GitHub, Google, HackerOne, OpenAI, Curl
Products: Gemini 3.5 Flash Cyber, CodeMender, Codex Security
Original source: thehackernews.com